Live data from Hacker News

How I could have hacked any Facebook account

anandpraka.sh

111–120 of 168 posts

Re: How I could have hacked any Facebook account

#111
post #65

Earlier quoted context omitted.

I agree. This was basically unrestricted access to any Facebook account. What a MASSIVE flaw. And who knows if this was already exploited in the wild? $15k is nothing at all compared to the scale of this issue...

Doesn't Facebook alert the user if it detects suspicious account login activity from an unknown location or IP?

The SMS and the e-mail about the password change is already a big alert for the user.

Re: How I could have hacked any Facebook account

#112

Earlier quoted context omitted.

I agree. This was basically unrestricted access to any Facebook account. What a MASSIVE flaw. And who knows if this was already exploited in the wild? $15k is nothing at all compared to the scale of this issue...

It's not really unrestricted. Given that this is forcing the password reset, you can't silently do it, right? So anyone exploiting it knows there's a limited number of uses before people notice that their passwords are being reset by not them.

True, the restriction is that you only get a guarantee of getting in one time. I meant that there are no restrictions on what you can do once you're in. (E.g. a XSS chat hack or something like that would be restricted in that sense)

Re: How I could have hacked any Facebook account

#113
post #97

beta.facebook.com and mbasic.beta.facebook.com Certificate Transparency has an interesting impact on some of the less-public servers. https://crt.sh/?q=%25.facebook.com A host of servers turn up in that list, which may similarly be less security tested than the main facebook.com site.

I'm surprised an organisation as large as Facebook don't have their own CA, and just don't issue the semi-secret stuff off the record.

Running a CA is a major pain, adds auditing and other requirements that are ongoing pain, and prior to the past year or so Facebook did not issue enough certificates to make the cost worthwhile. Doing this right means adding a lot of logging and access control around a few parts of the infra stack that would manage this, so why not pay someone else to deal with the paperwork and bother? All FB certs are on the CT logs as a matter of policy, so that there are no loopholes in our current statement that if a Facebook cert is not on the CT logs you should not consider it valid; we will accept the loss of secrecy (and people launching new stuff hate it but have learned to adjust) if the end result is making it harder for someone to slide a dodgy cert into the chain.

Re: How I could have hacked any Facebook account

#114
post #23

Earlier quoted context omitted.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

where do people even go to start to sell an exploit? how does that kind of stuff work?

same place as silk road.

Re: How I could have hacked any Facebook account

#115

Earlier quoted context omitted.

Your comments make sense in the real world, where the big threat is "criminal enterprise looking to make an illicit buck". I worry that people are too obsessed about the hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun, rather than for a pay-off, e.g. ZF0.

>* hypothetical specter of tremendously skilled and bored black-hats who will ruin lives for fun* I'd assume having $15k to spend is a lot more fun than any enjoyment one could have by hacking someone's facebook account. You'd have to have a real vendetta against someone to value ruining their life at $15k.

For a political hit, $15k might be a very reasonable valuation.

Re: How I could have hacked any Facebook account

#116

Earlier quoted context omitted.

Yeap, you're right. These guys at least aren't paying a bounty for Facebook/Google bugs: https://www.zerodium.com/program.html

Footnote on the graphic: *All payout amounts are chosen at the discretion of ZERODIUM and are subject to change or cancellation without notice. Translation: "Show us what you got and then we'll screw you over." Sounds like you're less likely to get screwed by an escrow service found on TOR.

Or simply publishing it first and leveraging to opportunity for contract work. I'd really hope you're able to get a commitment from ZERODIUM before giving them the details.

Re: How I could have hacked any Facebook account

#117
post #23

Earlier quoted context omitted.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

where do people even go to start to sell an exploit? how does that kind of stuff work?

I assume you're wondering about the black market? Traditionally, Russian and Eastern European carder forums. In the golden age of Western Union and Moneygram... More recently, dark web markets over TOR with multi-sig cryptocurrency escrow.

Re: How I could have hacked any Facebook account

#118
post #77
post #75

Earlier quoted context omitted.

You know what people put into Facebook chats? Obligatory quote from Kanye's newest album 'The Life of Pablo': " I had a cousin that stole my laptop that I was fuckin' bitches on Paid that nigga 250 thousand just to get it from him "

You know what people put into Instant Bloomberg chats? Go try to sell an IBB bug.

[deleted]

Re: How I could have hacked any Facebook account

#119
post #23
post #8

Frankly I think the amount being award by these companies is minuscule when you compare it to the amount of damage this information could have caused Facebook in the wrong hands.

During the fiasco that was the last white-hat hacker to report he'd hacked Facebook, I posted this: > Bug bounties are supposed to represent a high probability payoff of a lesser amount of money for finding a bug. This is in comparison to going the black hat sales root, where probability of sale might be lower, but the payoff might be higher. I can imagine one or two state actors who might pay top dollar to have keys…

Another factor is that when you are buying on black market, you can't be sure whether you are buying real exploit or fake one. Exploit owner probably will request (irreversible) bitcoin payment, will communicate via anonymous channels and is unlikely to give out details about that exploit until he's got his money. So both sides have difficulty trusting each other. Probably solution is some trusted 3-rd party, but is there one in black market? It's hard to imagine, actually.

Re: How I could have hacked any Facebook account

#120
post #12

Earlier quoted context omitted.

I suspect most whitehat researchers would be happier to report this vulnerability and make a nice legal reward, then delve into a black hat market for selling a vulnerability. Seems pretty win-win in this case.

Unless your name is Kevin Mitnick. Then you set up a business and play middlemen in selling them to anybody who wants to pony up for it. "When we have a client that wants a zero-day vulnerability for whatever reason, we don’t ask, and in fact they wouldn’t tell us,” Mitnick tells WIRED in an interview. “Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between.” h…

How is this legal?
Post reply on HN